Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
N3 Wireless N150 CRITICAL 9.8
CVE-2015-5995EPSS 19%

Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attackers to obtain administrative a…

Fix: after 5.07.50
Fix from $2,300 2015-12-31
Cg Wlbargs Firmware CRITICAL 9.8
CVE-2015-7792

Corega CG-WLBARGS devices allow remote attackers to perform administrative operations via unspecified vectors.

No fix yet
Fix from $2,300 2015-12-30
Wl 330nul Firmware HIGH 7.3
CVE-2015-7788

ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to execute arbitrary commands via unspecified vectors.

Fix: after 3.0.0.41
Fix from $1,950 2015-12-30
Winrar HIGH 7.4
CVE-2015-5663

The file-execution functionality in WinRAR before 5.30 beta 5 allows local users to gain privileges via a Trojan horse file with a name similar to an…

Fix: after 5.30
Fix from $1,950 2015-12-30
Ubuntu Linux HIGH 7.2
CVE-2015-5252EPSS 13%

vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships e…

Fix: 4.1.22 / 4.2.7+
Fix from $1,950 2015-12-29
Vplex Geosynchrony HIGH 8.4
CVE-2015-6850

EMC VPLEX GeoSynchrony 5.4 SP1 before P3 and 5.5 before Patch 1 has a default password for the root account, which allows local users to gain privile…

No fix yet
Fix from $1,950 2015-12-28
Linux Kernel MEDIUM 6.7
CVE-2015-8660EPSS 22%

The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local …

Fix: 3.18.31 / 4.1.22+
Fix from $1,600 2015-12-28
Ad Self Password Reset CRITICAL 10.0
CVE-2015-8267

The PasswordReset.Controllers.ResetController.ChangePasswordIndex method in PasswordReset.dll in Dovestones AD Self Password Reset before 3.0.4.0 all…

Fix: after 3.0.3.0
Fix from $2,300 2015-12-24
Isilon Onefs HIGH 8.0
CVE-2015-4545

EMC Isilon OneFS 7.1 before 7.1.1.8, 7.2.0 before 7.2.0.4, and 7.2.1 before 7.2.1.1 allows remote authenticated administrators to bypass a SmartLock …

Fix: after 7.1.1.7
Fix from $1,950 2015-12-21
Searchblox CRITICAL 10.0
CVE-2015-7919EPSS 22%

SearchBlox 8.3 before 8.3.1 allows remote attackers to write to the config file, and consequently cause a denial of service (application crash), via …

Mitigation only
Fix from $2,300 2015-12-21
Mobile Platform HIGH 7.5
CVE-2015-8600

The SysAdminWebTool servlets in SAP Mobile Platform allow remote attackers to bypass authentication and obtain sensitive information, gain privileges…

Mitigation only
Fix from $1,950 2015-12-17
Web Vulnerability Scanner HIGH 7.2
CVE-2015-4027

The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users to gain privileges via a comma…

Fix: after 10
Fix from $1,950 2015-12-17
Fedora HIGH 7.4
CVE-2015-8370

Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, o…

Patch available
Fix from $1,950 2015-12-16
Total Security 2015 MEDIUM 6.4
CVE-2015-8579

Kaspersky Total Security 2015 15.0.2.361 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresses when protecting user-m…

No fix yet
Fix from $1,600 2015-12-16
Internet Security MEDIUM 6.4
CVE-2015-8578

AVG Internet Security 2015 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresses when protecting user-mode processes,…

No fix yet
Fix from $1,600 2015-12-16
Active Directory Self Service HIGH 7.4
CVE-2015-8570

The password reset functionality in Lepide Active Directory Self Service allows remote authenticated users to change arbitrary domain user passwords …

Mitigation only
Fix from $1,950 2015-12-15
Videoscape Distribution Suite Service Manager MEDIUM 6.5
CVE-2015-6417

Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.4.0 and earlier does not always use RBAC for backend database access, which allows rem…

Mitigation only
Fix from $1,600 2015-12-12
Prime Service Catalog MEDIUM 6.5
CVE-2015-6395

Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows remote attackers to modify th…

Mitigation only
Fix from $1,600 2015-12-12
Mac Os X HIGH 10.0
CVE-2015-7071

The File Bookmark component in Apple OS X before 10.11.2 allows attackers to bypass a sandbox protection mechanism for app scoped bookmarks via a cra…

Fix: after 10.11.1
Fix from $1,950 2015-12-11
Mac Os X HIGH 7.2
CVE-2015-7063

The kernel loader in EFI in Apple OS X before 10.11.2 allows local users to gain privileges via a crafted pathname.

Fix: after 10.11.1
Fix from $1,950 2015-12-11
Mac Os X HIGH 7.2
CVE-2015-7052

kext tools in Apple OS X before 10.11.2 mishandles kernel-extension loading, which allows local users to gain privileges via unspecified vectors.

Fix: after 10.11.1
Fix from $1,950 2015-12-11
Iphone Os HIGH 9.3
CVE-2015-7051

MobileStorageMounter in Apple iOS before 9.2 and tvOS before 9.1 mishandles the timing of trust-cache loading, which allows attackers to execute arbi…

Fix: after 9.1
Fix from $1,950 2015-12-11
Watchos MEDIUM 6.8
CVE-2015-7001

AppSandbox in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 mishandles hard links, which allows attackers to byp…

Fix: after 10.11.1
Fix from $1,600 2015-12-11
Flash Player HIGH 10.0
CVE-2015-8440EPSS 6%

Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.…

Fix: after 19.0.0.241
Fix from $1,950 2015-12-10
Windows 10 HIGH 7.2
CVE-2015-6174

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2…

Patch available
Fix from $1,950 2015-12-09
Windows 10 HIGH 7.2
CVE-2015-6173

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2…

Patch available
Fix from $1,950 2015-12-09
Windows 10 HIGH 7.2
CVE-2015-6171

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2…

Patch available
Fix from $1,950 2015-12-09
Edge MEDIUM 6.8
CVE-2015-6170EPSS 9%

Microsoft Edge allows remote attackers to gain privileges via a crafted web site, aka "Microsoft Browser Elevation of Privilege Vulnerability."

No fix yet
Fix from $1,600 2015-12-09
Edge HIGH 9.3
CVE-2015-6139EPSS 15%

Microsoft Internet Explorer 11 and Microsoft Edge mishandle content types, which allows remote attackers to execute arbitrary web script in a privile…

Mitigation only
Fix from $1,950 2015-12-09
Windows 10 HIGH 7.2
CVE-2015-6133EPSS 67%

Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle library loading, w…

Patch available
Fix from $1,950 2015-12-09